www.manifold.security Scams Exploit Placeholder Domains in AI Agent Skills
Article Content
- •Two placeholder domains redirect macOS users to scams.
- •Static checks failed to detect malicious redirects due to JavaScript execution.
- •The issue affects 359,000 GitHub files and 349 AI agent skills.
Manifold Security discovered that unreserved placeholder domains, specifically yoursite.com and your-domain.com, are redirecting macOS users to scams. These domains, found in 359,000 GitHub files and cited by 349 AI agent skills, serve cloaked scam redirects without any changes to the original code. Researchers tested these domains across 24 real-browser sessions, where two visits led to scam pages while others ended on parking or ad pages. The scams included a fake 'MacOS Security Center' warning and counterfeit news articles promoting investment schemes. Static checks failed to identify the malicious redirects, which only activated after JavaScript execution in a real browser. This issue highlights the risks associated with using non-reserved domains in software documentation. The findings follow a previous disclosure about another placeholder domain, third-party.com, which was turned into a ClickFix lure targeting Windows users.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track ClickFix and Manifold Security in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Russia's AI-Driven Cyber Espionage Targets Ukraine and Europe A Russian-linked hacking group, identified as GTG-20006, has utilized Anthropic's Claude AI to automate cyber espionage against over 20 organizations, primarily in Ukraine and Europe. The group targeted Ukrainian government officials, military personnel, and drone manufacturers through sophisticated phishing and…
New ChainScript RAT Exploits ClickFix Lures with Blockchain C2 A newly discovered Node.js remote access trojan (RAT) named ChainScript is being deployed through ClickFix social engineering tactics, targeting Windows systems. The malware utilizes a unique command-and-control (C2) discovery method by querying a Polygon blockchain smart contract to dynamically rotate its server…